Customer service matters, even for data protection folk
The rarest thing in modern customer service, it seems, is a flesh-and-blood human. Instead, we’re offered chatbots, interactive tools and of course, download another app. A telephone number or even a direct email address? Good luck! Good customer service is dying, but here’s my take on why organisations should take it a more seriously. And not just obvious customer-facing teams, but also those responsible for handling data protection queries, requests and complaints.
Data protection is, by default, one of the departments of last resort. By the time someone gets in touch with the data protection team (or the sole person whose been nominated to take care of such matters), they’re unhappy about something else. Data protection ends up in the firing line of angry customers, enraged clients or irked former employees. When people are already frustrated by their treatment by another department, it should be even more important to treat them with respect and care. Even if, they’re being a downright nuisance.
I very rarely contact data protection teams, perhaps out of solidarity: I don’t want to trouble them. But let me tell you why I recently did.
A well-known retailer got under my skin. After a protracted battle to get a refund, I finally gave up and angrily walked away. Their customer service was genuinely appalling. So, I was deeply annoyed to receive a customer satisfaction survey six months later. I firmly asked to be removed from their list and surprisingly got a positive response. BUT, a month later, another survey dropped into my inbox. Now, on the war path, I deployed my “particular set of skills.” I scoured their privacy notice and submitted an erasure request. That’ll teach ’em!
And there we have it: a clear case of the data protection team taking flak due to the actions of others. However, despite an opportunity for the company to redeem themselves, matters haven’t improved. More than a month later. Zero. Nada. Zilch. Poor customer service is clearly baked in across ALL departments, and my opinion of the company unlikely to ever recover. I’m too classy to name names… yet.
I began my data protection journey more than twenty years ago, handling people’s complaints about where their personal details were sourced, what they were being used for, who they’d been shared with and so on. I also handled subject access requests. I quickly had to learn how to take the heat out of a situation. In those days it involved a real person (me) having my wits about me on the phone as Mister Angry from Tunbridge Wells vented his spleen.
My approach, though, worked more often than not: treat people with respect, communicate kindly and keep them updated. Clearly explain things, perhaps apologising when things have clearly gone wrong. This can go some way to prevent complaints escalating. If everyone does this, your data protection team may not be so busy. When I say ‘customers’ this can include anyone from tenants, patients, service users, students, members and so on. I’d take this further to how job applicants and employees are treated.
I know, in the real world, inevitably matters will end up in a data protection request or complaint. But here too, good customer service and communications matter.
Let’s take the dreaded DSAR as an example.
An abrupt and clinical acknowledgement, along with an equally curt response offering little explanation? It’s inviting the individual to come straight back at you, taking up yet more of your time. A more considered and helpful acknowledgement, updates along the way, with a meaningful covering letter accompanying your pack of their personal data? That leaves a much better impression. Sometimes, “front-loading” your work in this manner actually saves time, money and effort in the long run.
Of course, there’s no placating some people, but should just give up? I don’t think so. Not least, good ‘customer service’ might just shine through if the ICO should ever pore over your correspondence. It demonstrates good faith.
My next steps with the awful retailer? I’m planning on raising my first ever data protection complaint. Oh wait, of course, they haven’t explained how I can do this! I’ll persevere. And you know what? I might, if I have to, just take this one to the ICO. The retailer has irked me that much.
My revenge mission, incidentally, neatly brings me to the recent publication of the criteria the ICO uses to assess whether to investigate the complaints they receive. I’ve written more about this here.
Of course, being irked over a failed erasure request is unlikely to be considered significant, but it turns out just may be if eleven other people submit complaints in the same month as me about the same retailer, the regulator may start to sniff around.